OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.54 Mb Total Physical Memory | 394.70 Mb Available Physical Memory | 38.94% Memory free
2.38 Gb Paging File | 1.84 Gb Available in Paging File | 77.08% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 45.82 Gb Free Space | 61.53% Space Free | Partition Type: NTFS
Drive D: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: FRONT-DESK
Current User Name: SPerrigo
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/14 21:35:35 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\OTL.exe
PRC - [2009/10/07 09:36:07 | 02,023,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/08/23 21:22:29 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/23 21:22:29 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/23 21:22:25 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/07/26 16:44:34 | 03,883,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2009/07/24 18:32:40 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PRC - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/05/26 21:06:32 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
PRC - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/04/22 20:27:25 | 00,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2009/04/22 20:27:25 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/04/22 20:27:24 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE
PRC - [2009/02/06 17:07:48 | 00,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/12/25 10:46:43 | 00,185,872 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/12/08 15:50:04 | 00,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2008/11/09 16:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/16 20:11:26 | 00,569,344 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
PRC - [2008/10/16 20:11:26 | 00,184,320 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
PRC - [2008/10/16 19:23:30 | 00,214,360 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/10/16 19:15:38 | 00,344,064 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
PRC - [2008/10/16 18:26:40 | 00,116,016 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
PRC - [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2007/03/06 13:24:42 | 00,629,248 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.3\J2GTray.exe
PRC - [2007/03/06 13:21:31 | 00,116,224 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
PRC - [2006/08/28 22:57:12 | 00,395,776 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/07/21 17:50:10 | 00,086,016 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2006/07/21 17:47:00 | 00,081,920 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe
PRC - [2006/05/08 12:16:14 | 00,278,528 | ---- | M] (Dell) -- C:\Program Files\DELL\Dell Laser MFP 1815\NETWORKSCAN\DNSCST.EXE
PRC - [2006/05/01 09:07:44 | 00,843,776 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2006/03/17 18:25:16 | 00,065,536 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
PRC - [2005/06/23 17:31:48 | 00,053,248 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2004/10/28 15:03:32 | 00,327,680 | ---- | M] (KYOCERA MITA) -- C:\Program Files\Kyocera\FileUtility\nsCatCom.exe
PRC - [2003/09/16 16:50:18 | 00,061,440 | ---- | M] (KYOCERA MITA CORPORATION) -- C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
PRC - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2003/04/01 12:33:00 | 00,053,248 | ---- | M] (ali) -- C:\USBStorage\USBDetector.exe
========== Win32 Services (SafeList) ==========
SRV - File not found -- -- (RoxLiveShare9 [Auto | Stopped])
SRV - File not found -- -- (CLTNetCnService [Auto | Stopped])
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/08/23 21:22:25 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2009/08/05 22:48:42 | 00,704,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc [On_Demand | Stopped])
SRV - [2009/07/24 18:20:43 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca0cacfe52a8fe [Auto | Stopped])
SRV - [2009/07/24 18:19:52 | 00,190,448 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped])
SRV - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running])
SRV - [2009/04/22 20:27:24 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/11/09 16:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService [Auto | Running])
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2008/10/16 20:12:28 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
SRV - [2008/10/16 19:30:28 | 00,634,880 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -- (HPSLPSVC [Auto | Running])
SRV - [2008/10/16 19:24:24 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/07/18 13:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008/07/18 13:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/02/25 14:25:05 | 00,658,432 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/03/17 18:25:16 | 00,065,536 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe -- (ASFIPmon [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2003/09/16 16:50:18 | 00,061,440 | ---- | M] (KYOCERA MITA CORPORATION) -- C:\Program Files\Kyocera\FileUtility\SFUSVC.exe -- (SFUSVC [Auto | Running])
SRV - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1061216
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1061216
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1061216
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DellNSCST_GRNCH] C:\Program Files\DELL\Dell Laser MFP 1815\NETWORKSCAN\DNSCST.EXE (Dell)
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [eFax 4.3] C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Synchronization Manager] C:\WINDOWS\System32\mobsync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USBDetector] C:\USBStorage\USBDetector.exe (ali)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe File not found
O4 - HKCU..\Run: [Spyware Striker Pro] C:\Program Files\Ascentive\Spyware Striker\SpywareStriker.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe (j2 Global Communications, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Scanner File Utility.lnk = C:\Program Files\Kyocera\FileUtility\NsCatCom.exe (KYOCERA MITA)
O4 - Startup: C:\Documents and Settings\sperrigo.HARBORVIEW\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1239670503359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1239670486203 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = harborview.local
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/06/10 07:36:44 | 00,000,033 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\eflashcard.exe -- [2008/10/01 08:33:22 | 03,660,975 | R--- | M] (Macromedia, Inc.)
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\eflashcard.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[2009/10/09 19:08:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/14 21:33:26 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/09 19:08:34 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/10/09 19:08:09 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/10/09 19:04:04 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/10/10 10:06:58 | 00,000,000 | ---D | C] -- C:\Program Files\Safari
[2099/01/01 12:00:00 | 00,000,000 | --SD | C] -- \\SERVER\Users\sperrigo\My Documents\My Data Sources
[2099/01/01 12:00:00 | 00,000,000 | R--D | C] -- \\SERVER\Users\sperrigo\My Documents\My Videos
[2099/01/01 12:00:00 | 00,000,000 | R--D | C] -- \\SERVER\Users\sperrigo\My Documents\My Pictures
[2099/01/01 12:00:00 | 00,000,000 | R--D | C] -- \\SERVER\Users\sperrigo\My Documents\My Music
[2099/01/01 12:00:00 | 00,000,000 | -HSD | C] -- \\SERVER\Users\sperrigo\My Documents\RECYCLER
[2099/01/01 12:00:00 | 00,000,000 | ---D | C] -- \\SERVER\Users\sperrigo\My Documents\My Scans
[2099/01/01 12:00:00 | 00,000,000 | ---D | C] -- \\SERVER\Users\sperrigo\My Documents\My Received Files
[2099/01/01 12:00:00 | 00,000,000 | ---D | C] -- \\SERVER\Users\sperrigo\My Documents\LimeWire
[2099/01/01 12:00:00 | 00,000,000 | ---D | C] -- \\SERVER\Users\sperrigo\My Documents\eFax Messenger 4.3
[2009/10/14 21:35:28 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\OTL.exe
[2009/10/14 21:33:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/14 21:33:02 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\erunt_setup.exe
[2009/10/14 09:10:28 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\RootRepeal.exe
[2009/10/14 08:51:31 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\TFC.exe
========== Files - Modified Within 14 Days ==========
[2009/10/14 21:37:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/14 21:35:35 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\OTL.exe
[2009/10/14 21:33:34 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/14 21:33:31 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\NTREGOPT.lnk
[2009/10/14 21:33:30 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\ERUNT.lnk
[2009/10/14 21:33:15 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\erunt_setup.exe
[2009/10/14 20:30:21 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/10/14 10:45:51 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/14 10:45:46 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/14 10:43:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/14 10:43:49 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/14 10:43:47 | 10,628,46464 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/14 09:10:45 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\settings.dat
[2009/10/14 09:10:43 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\RootRepeal.exe
[2009/10/14 08:51:40 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\TFC.exe
[2009/10/14 07:53:24 | 42,812,116 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/10/14 07:53:24 | 00,027,205 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/10/14 07:46:41 | 01,702,912 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\BeachCondo3ESLIDESHOW[1].ppt
[2009/10/10 10:07:17 | 00,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/10/09 19:09:44 | 00,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/10/09 19:04:28 | 00,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/10/09 12:22:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/04 13:08:27 | 00,250,972 | ---- | M] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\FAR-9_Format[1].pdf
[2009/10/04 07:34:09 | 00,528,020 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/04 07:34:09 | 00,445,702 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/10/04 07:34:09 | 00,072,924 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/02 14:25:53 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2009/10/01 12:32:38 | 00,492,629 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
========== Files - No Company Name ==========
[2099/01/01 12:00:00 | 04,827,345 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Aimee Hall's docs.pdf
[2099/01/01 12:00:00 | 03,052,494 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\reach local 401k.pdf
[2099/01/01 12:00:00 | 01,987,381 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Georgesappraisal.pdf
[2099/01/01 12:00:00 | 01,196,032 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Independant Salvage receipt.doc
[2099/01/01 12:00:00 | 00,440,832 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Jose Martinez proof of payment.doc
[2099/01/01 12:00:00 | 00,273,835 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\reach local handbook.pdf
[2099/01/01 12:00:00 | 00,182,073 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\reach local confidentiality.pdf
[2099/01/01 12:00:00 | 00,151,735 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Florida Bar Opinion.pdf
[2099/01/01 12:00:00 | 00,075,264 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\2008 MFKL Draft Grid.xls
[2099/01/01 12:00:00 | 00,039,268 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\2008 1009 Nationwide.pdf
[2099/01/01 12:00:00 | 00,037,376 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\2007 draft grid(1).xls
[2099/01/01 12:00:00 | 00,032,220 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Steven - Blue line.pdf
[2099/01/01 12:00:00 | 00,028,672 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\raypayagreement.doc
[2099/01/01 12:00:00 | 00,025,213 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\reach local pay agreement.pdf
[2099/01/01 12:00:00 | 00,024,576 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\jbrightletter.doc
[2099/01/01 12:00:00 | 00,024,576 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Familus letter.doc
[2099/01/01 12:00:00 | 00,024,064 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\what i want to do in fl..doc
[2099/01/01 12:00:00 | 00,024,064 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\inquiry letter.doc
[2099/01/01 12:00:00 | 00,024,064 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\familusfaxtobusiness.doc
[2099/01/01 12:00:00 | 00,024,064 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\familius insurance.doc
[2099/01/01 12:00:00 | 00,024,064 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\Doc1.doc
[2099/01/01 12:00:00 | 00,021,504 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\October 2007 Evolution.xls
[2099/01/01 12:00:00 | 00,019,968 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\resume.doc
[2099/01/01 12:00:00 | 00,013,824 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\gordy breakdown.xls
[2099/01/01 12:00:00 | 00,000,839 | ---- | C] () -- \\SERVER\Users\sperrigo\My Documents\My Sharing Folders.lnk
[2009/10/14 21:33:34 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/14 21:33:31 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\NTREGOPT.lnk
[2009/10/14 21:33:30 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\ERUNT.lnk
[2009/10/14 09:10:45 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\settings.dat
[2009/10/14 07:46:41 | 01,702,912 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\BeachCondo3ESLIDESHOW[1].ppt
[2009/10/10 10:07:17 | 00,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/10/09 19:09:44 | 00,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/10/09 19:04:27 | 00,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/10/04 13:08:27 | 00,250,972 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Desktop\FAR-9_Format[1].pdf
[2009/10/02 14:25:53 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2009/08/16 15:25:36 | 00,223,232 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll
[2009/08/16 15:25:36 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\SQLiteWrapper.dll
[2009/02/01 10:41:00 | 04,845,758 | -H-- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Local Settings\Application Data\IconCache.db
[2008/03/13 12:04:33 | 00,000,066 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2008/02/19 17:52:55 | 00,019,569 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/01/15 15:50:04 | 00,000,142 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Local Settings\Application Data\fusioncache.dat
[2008/01/15 15:49:16 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\desktop.ini
[2008/01/15 15:49:15 | 00,018,328 | ---- | C] () -- C:\Documents and Settings\sperrigo.HARBORVIEW\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/01/15 13:23:49 | 00,000,060 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/08/09 09:20:12 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2007/06/07 13:46:08 | 00,000,036 | ---- | C] () -- C:\WINDOWS\marscam.ini
[2007/03/29 12:02:02 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2007/03/20 15:10:16 | 00,000,174 | ---- | C] () -- C:\WINDOWS\nscatch.ini
[2007/02/15 16:35:17 | 00,000,058 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\mchguid.ini
[2007/01/17 17:33:35 | 00,000,256 | ---- | C] () -- C:\WINDOWS\AddrEdit.ini
[2007/01/11 14:53:57 | 00,094,208 | R--- | C] () -- C:\WINDOWS\System32\WIAIPH.dll
[2007/01/11 14:53:57 | 00,086,016 | R--- | C] () -- C:\WINDOWS\System32\WIAEH.dll
[2007/01/11 14:53:57 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\WIASTIIO.dll
[2007/01/11 14:53:57 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\Sswiadrv.dll
[2007/01/11 14:52:50 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\DELG1CI.dll
[2007/01/11 14:52:49 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\SVSetup.dll
[2007/01/11 14:52:34 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\d1815ci.dll
[2007/01/11 14:52:33 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\VdSetup.dll
[2007/01/11 14:52:33 | 00,022,663 | ---- | C] () -- C:\WINDOWS\System32\DELG1LMK.DLL
[2007/01/04 15:17:18 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PNTINFO.INI
[2007/01/02 12:39:00 | 00,000,058 | ---- | C] () -- C:\WINDOWS\mchguid.ini
[2007/01/02 11:27:14 | 00,010,875 | ---- | C] () -- C:\WINDOWS\ESOA.INI
[2007/01/02 11:27:14 | 00,003,679 | ---- | C] () -- C:\WINDOWS\GrAddrBk.ini
[2007/01/02 11:27:14 | 00,000,995 | ---- | C] () -- C:\WINDOWS\GRACE.INI
[2007/01/02 11:27:14 | 00,000,053 | ---- | C] () -- C:\WINDOWS\PRSRVDLL.INI
[2007/01/02 11:26:17 | 00,001,575 | ---- | C] () -- C:\WINDOWS\winpoint.ini
[2006/12/16 02:30:17 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/12/16 02:26:43 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/12/16 02:03:33 | 00,348,880 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2006/12/16 02:03:33 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4642.dll
[2006/12/16 02:01:43 | 00,000,391 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/07/31 01:59:36 | 00,000,338 | ---- | C] () -- C:\WINDOWS\scrub2k.ini
[2006/01/24 11:33:16 | 00,221,184 | ---- | C] () -- C:\WINDOWS\System32\ExpLoansFromGenesis.dll
[2004/08/11 18:24:19 | 00,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 18:07:11 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/11 18:00:37 | 00,000,844 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/11 18:00:35 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/11/12 10:16:58 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\GNetParserX.dll
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2000/02/17 14:57:02 | 00,225,280 | ---- | C] () -- C:\WINDOWS\System32\GN32.DLL
[1999/10/13 15:59:48 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\GNS2KZIP.DLL
========== LOP Check ==========
[2009/10/09 19:08:09 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/10/09 19:09:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/14 14:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/17 15:30:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ascentive
[2009/09/20 16:16:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2008/01/22 12:28:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
[2008/01/22 12:28:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
[2009/07/30 15:07:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2007/01/17 17:48:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kyocera Mita
[2008/03/05 14:49:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/07/30 15:09:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone DEMO
[2009/04/15 08:39:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Roxio
[2004/08/11 18:25:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2007/04/30 11:10:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/09/20 16:16:37 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data
[2009/08/16 16:37:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\Ascentive
[2009/09/20 16:16:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\AVS4YOU
[2008/01/22 12:28:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\eFax Messenger
[2008/03/04 11:04:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\Encompass
[2008/03/05 14:19:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\Image Zone Express
[2009/02/13 17:29:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\LimeWire
[2008/03/05 14:19:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\Printer Info Cache
[2008/10/26 23:56:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\sperrigo.HARBORVIEW\Application Data\U3
[2009/10/09 12:22:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 06:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/14 20:30:21 | 00,000,868 | ---- | M] () -- C:\WINDOWS\Tasks\Google Software Updater.job
[2009/10/14 10:45:51 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/14 21:37:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/10/14 10:43:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32\eventlog.dll >
[2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
< >
< End of report >